Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
cyberluke365
Contributor
Jump to solution

At least one DC is currently disconnected > Bad Credentials

Hello,
I have an issue regarding AD Queries for Identity Awareness.

Environment: Check Point R81 + Take 56 (active/passive cluster)

The monitor shows a warning related to Identity Awareness: Error: At least one DC is currently disconnected; the AD Query Status shows Bad Credentials.

I double-checked credentials (they didn't expire); I also changed the password, test LDAPs (636 port) with ldp.exe tool and it is working. 

Any advice ? Is there any specific log I can check to better understand the issue ?

 

Thank you.

0 Kudos
1 Solution

Accepted Solutions
Ave_Joe
Contributor

I suspect that MS KB500442 was installed on the domain controllers.  I would check that first.

View solution in original post

(1)
3 Replies
Ave_Joe
Contributor

I suspect that MS KB500442 was installed on the domain controllers.  I would check that first.

(1)
cyberluke365
Contributor

Hello,
yes, you are completely right.
It seems a June 2022 enables hardening changes on DCOM.

There is this Check Point article Check Point response to CVE-2021-26414 - "Windows DCOM Server Security Feature B...

The best way to solve it, instead of disabling the behavior introduced by KB via registry key, is to install latest Check Point R81 take (Take 60 solves the issue).

Thank you,
Luca

 

Regards,
Luca

(1)
Paul_Kazzi
Participant

Yes indeed the latest HF resolved it   🙂

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events